Web browsers & smart cards
With respect to security, how does the Web browser handle the non-repudiation (digital signature) and encryption of a message using a smart card? The smart card contains a user private key. Is it really secure (as compared to a window message client)?


    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

A Web browser handles the non-repudiation and encryption of a message using a smart card just as when using the technology on a desktop computer, except the private key is stored on the card. Software will require a passphrase (or biometrics) to access the private key; hence we have something the user knows -- passphrase and something he has -- the card.

There is no fundamental difference between a smart card and window message client except that a person can carry his smart card from computer to computer, making his identity more portable (not tied to a particular desktop or notebook PC).


This was first published in April 2001